Process injection into browser processes from unsigned or unrecognized process

Detects unauthorized process injection attempts—such as remote thread creation, memory writes, or OpenProcess calls—targeting browser processes (chrome.exe, firefox.exe). The rule filters out known-legitimate security tools and browser helper processes by leveraging process names, company metadata, and valid digital signatures. This activity is indicative of credential or crypto wallet theft, as seen in stealers like Dolphin X.