Access To Browser Credential Files By Uncommon Applications — Detection Rule

Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage

Read the full analysis on IntelFusions