BioShocking: Browser Rapid Access to Multiple Sensitive Internal URL Paths

Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.