Sality-style keyboard hook install and browser credential store access
This rule detects potential credential and keystroke theft by identifying the installation of a Windows hook (SetWindowsHookEx) followed within 30 minutes by file access to sensitive browser credential stores (Login Data, key4.db, etc.) by the same process on a single device.
Microsoft Sentinel (KQL)

