Process accessing Chrome/Edge/Firefox credential store files (PureLog Stealer)

This rule detects when common Windows LOLBins (Living-off-the-Land Binaries) or scripting hosts attempt to read, create, modify, or rename sensitive credential storage files (such as login databases and cookies) associated with popular web browsers like Chrome, Edge, and Firefox. Such behavior is a common indicator of credential theft activity by information-stealing malware.