Infostealer Recon — Rapid Multi-Sensitive-File Access (T1552.001)

Detects unauthorized processes attempting to access or perform operations on sensitive files such as browser credentials, SSH keys, crypto wallets, and password manager databases. The rule specifically looks for non-standard or unsigned processes interacting with a high volume of these files in a short time frame, which is indicative of credential harvesting by infostealer malware like Lumma, Redline, or Vidar.