Access To Browser Credential Files By Uncommon Applications — Detection Rule
Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage