Browser Credential Store Access by Non-Browser Process (Infostealer)
Detects unauthorized processes attempting to read, modify, or create files within common browser credential locations (Chrome, Firefox, Edge, and Windows Credential Manager). Legitimate browser processes and their known signers are excluded, focusing on suspicious secondary processes or tools frequently utilized by infostealers like Lumma and RedLine to dump credentials.
SentinelOne

