Non-browser process accessing Chrome/Edge Login Data or Cookies DB
Detects unauthorized processes attempting to access sensitive browser data files, specifically 'Login Data' (passwords) and 'Cookies' for Google Chrome and Microsoft Edge. The rule excludes the browser applications themselves and their update processes to minimize noise.
Splunk (SPL)

