BabylonRAT-Style Browser Credential Store Access by Non-Browser Process
Detects unauthorized processes attempting to access browser credential database files such as Login Data for Chromium-based browsers or logins.json and key4.db for Firefox. The rule filters out known browser processes to isolate potential credential harvesting or exfiltration activity.
CQL

