2026 Critical Enterprise Intrusion Chain Detection: Browser Credential Store Access by Untrusted Process
Detects unauthorized processes attempting to read or create sensitive browser credential files ('Login Data', 'Web Data', 'Cookies', 'logins.json', 'key4.db'). This activity is commonly associated with information-stealing malware (such as Lumma, StealC, Vidar, RedLine, and Amadey) that targets browser databases to extract stored secrets, often bypassing standard browser process access.
Microsoft Sentinel (KQL)

