BrowserCore.exe Executed with Stdin/Stdout Redirection for PRT Theft

Detects the execution of BrowserCore.exe, a native messaging component for web browsers, when combined with command-line redirection (< or >) or specific output file creation (e.g., prt_cookie.txt, formatted_nonce.txt). This behavior is characteristic of an attack designed to extract Primary Refresh Tokens (PRTs) or browser cookies, which can be used to bypass authentication mechanisms.