TokenGrabber Stealer: Lazy Module Load Followed by Wi-Fi/Persistence Command
Detects a suspicious pattern where a single process loads high-risk cryptography and system-level modules (e.g., sqlite3, win32crypt, win32api) followed within 30 minutes by credential harvesting actions such as dumping Wi-Fi keys using 'netsh' or establishing persistence via 'schtasks'. This behavior is indicative of a 'lazy-import' stealer or malicious loader attempting to evade simple signature-based detection.
Microsoft Sentinel (KQL)

