Possible ProtonVPN credential theft via config directory access
Detects file system access to the ProtonVPN local configuration directory. This directory may contain sensitive data, such as cached credentials or session information, which could be targeted by unauthorized actors to facilitate credential theft or session hijacking.
Sigma

