SHEETCREEP: Non-Browser CLR Process Exfiltrating Data via googleapis.com
Detects non-browser processes that load 'clr.dll' (indicating in-process .NET/CLR usage) and are sending large volumes of outbound data to Google API domains (sheets.googleapis.com, oauth2.googleapis.com, googleapis.com). This behavior is consistent with the SHEETCREEP threat actor's use of Google Sheets API for command and control (C2) and data exfiltration.
Microsoft Sentinel (KQL)

