Credential Store Access by Go/Node/Script Host on DevOps Workstation
Detects instances where common scripting or development language runtimes (Go, Node.js, WScript, CScript) access sensitive configuration or credential files, such as AWS credentials, Kubernetes configs, SSH keys, or environment files. This activity is often indicative of credential harvesting or unauthorized access to sensitive secrets by potentially malicious scripts or processes.
Sigma

