Non-Browser Process Access to Browser Credential Files

This rule detects instances where a process that is not a recognized web browser attempts to access sensitive files associated with browser credential stores, such as Login Data, Cookies, and web browser state files. Such activity is commonly associated with infostealer malware, which attempts to exfiltrate saved passwords, session cookies, and autofill information.