HEAVYGRAM Telegram Desktop tdata Session Exfiltration
Detects unauthorized access or file creation events targeting the 'tdata' directory, which stores local Telegram session and authentication data. The rule triggers when processes other than legitimate Telegram or system file explorers interact with these files, a common technique for session theft and account takeover.
SentinelOne

