HVNC Backdoor Accessing Firefox Credential/Session Databases
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
Microsoft Sentinel (KQL)

