Describe the bug
The "Sensitive File Access - Cloud Credentials" rule only supports Windows. Could it please be ported to Linux and macOS?
To Reproduce
- View https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/credential_access_sensitive_file_access_cloud_credentials.toml
- Notice that
os_list = ["windows"]
Expected behavior
Support for Linux and macOS (our primary platforms)
Desktop (please complete the following information):
Additional context
If it helps, we're new Defend customers, and credential theft is our #1 concern.