Browser Credential Store Access by Non-Browser Process (Firefox/Edge)

Detects unauthorized access, modification, or deletion attempts against common web browser credential storage files (key4.db, logins.json, and Microsoft Edge 'Login Data'). These files store sensitive authentication information, and non-browser processes interacting with them are indicative of credential harvesting attempts.