Most Significant TTP 2026: Credential Theft Companion Process filemanager.exe Ex

Detects the execution of 'filemanager.exe' and its subsequent access to sensitive browser credential stores (e.g., 'Login Data', 'cookies.sqlite'), occurring within a short window following a PowerShell-based ClickFix-style attack chain. The rule correlates initial suspicious script execution (often involving hidden windows, obfuscated commands, or web requests) with follow-on credential harvesting behavior on the same host.