Agentic Browser Automation Abuse for Credential Theft

This rule detects the execution of browser automation and testing tools (such as Playwright, Puppeteer, Selenium, and various browser drivers) when initiated by common, non-development-related parent processes like Microsoft Office applications, Explorer, or service hosts. This behavior is indicative of potential malicious activity, such as automated credential harvesting or unauthorized web interaction initiated by a compromised document or process.