AiTM Browser Credential File Access by Non-Browser Process (T1539/T1555.003)
Detects instances where non-browser processes access sensitive browser-related files (Login Data, Cookies, or Local State) located within AppData directories. This behavior is highly indicative of credential and session token theft, often associated with AiTM or post-compromise information harvesting activities.
SentinelOne

