Credential Theft Malware Activity Followed by Account Sign-In

This rule detects potential credential theft activity by monitoring for unauthorized access to sensitive browser-related credential files (e.g., Login Data, cookies.sqlite) or direct access to the LSASS process memory by non-standard browser processes. It further correlates these events with user sign-ins on previously unknown or unassociated devices within a short timeframe to identify potential account compromise.