AI Platform Credential Harvesting via Browser LocalStorage or IndexedDB Access
Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
SentinelOne

