Ransomware Series: Browser Credential/Cookie Store Theft by Non-Browser Process

This rule detects processes other than known web browsers (Chrome, Edge, Firefox, Brave, Opera) accessing sensitive browser-related files (Login Data, Cookies, Web Data) and initiating an external network connection within 15 minutes. This behavior is highly characteristic of credential and session cookie theft, often utilized by info-stealing malware for subsequent session hijacking.