Ransomware Series: Ransomware Credential Harvest via PowerShell ConsoleHost_hist

Detects unauthorized processes accessing the 'ConsoleHost_history.txt' file across user profiles. This behavior is indicative of ransomware operators or malicious actors attempting to harvest stored credentials, tokens, or sensitive command-line history before performing lateral movement or privilege escalation.