2026 Critical Enterprise Intrusion Chain Detection: Browser Credential Store Acc
Detects unauthorized access to sensitive Chromium-based browser files such as 'Login Data' (password database) or 'Local State' (encryption keys) by processes other than standard web browsers (Chrome, Edge, Brave, Firefox). The rule also elevates risk if the access is followed by the execution of known data-handling tools like sqlite, python, or powershell, which are frequently used by information stealers to parse and exfiltrate browser-stored credentials.
YARA-L

