SHEETCREEP APT36: Non-browser Google OAuth2 JWT auth from AppData or Temp
This rule detects network connections to Google API domains (oauth2.googleapis.com, accounts.google.com, or any *.googleapis.com on port 443) initiated by processes that are not common browsers or Google update/crash handler executables. The detection is further narrowed down to processes executing from 'AppData' or 'Temp' directories, or specifically 'vaultsvc.exe', which are often indicators of suspicious or malicious activity.
Microsoft Sentinel (KQL)

