Hunt for Password and Secret Files

Detects file creation, modification, or rename activity involving filenames that contain credential related indicators. The detection focuses on common document, spreadsheet, text, PDF, and archive formats that are frequently used to store sensitive authentication material. Such files may represent exposed credentials that could be leveraged by adversaries for credential access, privilege escalation, or lateral movement following endpoint compromise.