Stealer payload accessing developer secrets (.aws, .ssh, GitHub CLI, .env)

This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.