OnyxC2 Stealer - Chrome Extension IndexedDB and Local Storage Access by Non-Browser Process
This rule detects processes other than standard web browsers (Chrome, Edge, Brave) attempting to access sensitive directories within Chrome extension user data paths, such as IndexedDB, Local Storage, or Sync Data. Such activity is often indicative of credential or session cookie theft by malicious scripts or malware.
Splunk (SPL)

