Pre-encryption access to KeePass, VPN, and private key files
Detects access, reading, or modification of sensitive credential files (such as KeePass databases, VPN profiles, private SSH keys, and certificates) by a process. This behavior is often associated with pre-encryption staging for data exfiltration during ransomware attacks.
YARA-L

