RemusStealer Browser Credential SQLite File Access by Non-Browser Process
This rule monitors for file access events (Sysmon Event ID 11) targeting sensitive web browser files, including logins (passwords), cookies, and web data, by processes other than the legitimate browser executables. Such access is a strong indicator of credential theft or session hijacking attempts.
Splunk (SPL)

