Infostealer Browser Credential Theft via Login Data Access

This rule detects unauthorized processes attempting to create, modify, rename, or delete the 'Login Data' SQLite database files used by Google Chrome and Microsoft Edge to store saved credentials. By excluding legitimate browser processes and updates, the rule identifies potential credential theft attempts by infostealer malware or unauthorized actor tools.