DPAPI & OAuth Token Theft via Credential Manager or TokenBroker Cache Access

Detects unauthorized access to Windows Credential Manager files, TokenBroker OAuth cache files, or the loading of crypt32.dll from suspicious, user-writable directories (e.g., Temp, Downloads, Desktop) by non-Microsoft or non-system processes. This activity is indicative of credential theft, session hijacking, or attempts to abuse the Windows Data Protection API (DPAPI) to decrypt sensitive local secrets.