Infostealer browser credential access from suspicious paths (multi-file)
Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
Microsoft Sentinel (KQL)

