Browser Credential File Access by Non-Browser Process

This rule detects unauthorized attempts to create, modify, rename, or delete sensitive browser data files (such as Login Data, Cookies, key4.db, and logins.json) used for storing credentials. It monitors for access by processes that are not known browser executables or authorized system services, which is a common indicator of credential dumping by malicious software.