Browser Process Injection with Suspicious IPC File Interaction

This rule detects potential malicious process injection originating from web browsers (chrome.exe or msedge.exe) when followed by the creation or access of a hex-named text file in the C:\ProgramData directory within a 5-minute window. This behavior often suggests a staged attack where a browser process is used to inject malicious code, and subsequently reads or interacts with a dropped file used for persistence or command-and-control communication.