SHEETCREEP APT36: Non-browser Google OAuth2 JWT auth from AppData or Temp

This rule detects network connections to Google API domains (oauth2.googleapis.com, accounts.google.com, or any *.googleapis.com on port 443) initiated by processes that are not common browsers or Google update/crash handler executables. The detection is further narrowed down to processes executing from 'AppData' or 'Temp' directories, or specifically 'vaultsvc.exe', which are often indicators of suspicious or malicious activity.