Non-Browser Process Accessing Browser Credential/Cookie Stores
Detects unauthorized processes attempting to read sensitive browser credential and session data (e.g., 'Login Data', 'Cookies', 'Local State', 'cookies.sqlite', 'logins.json') located in common browser profile paths. This behavior is highly indicative of information-stealing malware attempting to extract saved passwords and session cookies for account hijacking and 2FA/SSO bypass.
Sigma

