Chrome/Edge Cookies, Login Data, and Local State file access for credential/session theft
Detects access, creation, or modification of sensitive browser files (Cookies, Login Data, Local State) associated with Google Chrome or Microsoft Edge. The rule specifically flags when these files are interacted with within standard user directories or when they are copied to known browser backup folders, a common behavior during credential theft or data staging.
Microsoft Sentinel (KQL)

