2026 Critical Enterprise Intrusion Chain Detection: Non-Browser Process Accessing Browser Credential/Cookie Stores
Detects access to sensitive browser credential and cookie files by processes that are not recognized web browsers or their designated update components. This behavior is highly indicative of credential theft activity where an adversary is attempting to extract stored credentials or session cookies from local browser storage.
Cortex XDR

